CVE-2018-1421
https://notcve.org/view.php?id=CVE-2018-1421
IBM WebSphere DataPower Appliances 7.1, 7.2, 7.5, 7.5.1, 7.5.2, and 7.6 is vulnerable to a XML External Entity Injection (XXE) attack when processing XML data. A remote attacker could exploit this vulnerability to expose sensitive information or consume memory resources. IBM X-Force ID: 139023. Las versiones 7.1, 7.2, 7.5, 7.5.1, 7.5.2 y 7.6 de IBM WebSphere DataPower Appliances son vulnerables a ataques de tipo XML External Entity Injection (XXE) al procesar datos XML. Un atacante remoto podría explotar esta vulnerabilidad para exponer información sensible o consumir recursos de la memoria. • http://www.ibm.com/support/docview.wss?uid=swg22015055 https://exchange.xforce.ibmcloud.com/vulnerabilities/139023 • CWE-611: Improper Restriction of XML External Entity Reference •
CVE-2017-1773
https://notcve.org/view.php?id=CVE-2017-1773
IBM DataPower Gateways 7.1, 7,2, 7.5, and 7.6 could allow an attacker using man-in-the-middle techniques to spoof DNS responses to perform DNS cache poisoning and redirect Internet traffic. IBM X-Force ID: 136817. IBM DataPower Gateways 7.1, 7,2, 7.5 y 7.6 podría permitir que un atacante que emplee técnicas de Man-in-the-Middle (MitM) suplante las respuestas DNS para realizar envenenamiento de caché DNS y redireccionar el tráfico de Internet. IBM X-Force ID: 136817. • http://www.ibm.com/support/docview.wss?uid=swg22012758 https://exchange.xforce.ibmcloud.com/vulnerabilities/136817 • CWE-345: Insufficient Verification of Data Authenticity •
CVE-2017-1591
https://notcve.org/view.php?id=CVE-2017-1591
IBM WebSphere DataPower Appliances 7.0.0 through 7.6 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 132368. IBM WebSphere DataPower Appliances versión 7.0.0 hasta 7.6, es vulnerable a ataques de tipo cross-site scripting. Esta vulnerabilidad permite a los usuarios insertar código JavaScript arbitrario en la interfaz de usuario web, y por lo tanto, alterar la funcionalidad deseada que podría conllevar a la divulgación de credenciales dentro de una sesión confiable. • http://www.ibm.com/support/docview.wss?uid=swg22008815 http://www.securityfocus.com/bid/101021 https://exchange.xforce.ibmcloud.com/vulnerabilities/132368 • CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') •